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We study the robustness of various protocols for quantum key distribution. We first consider the 
case of qutrits and study quantum protocols that employ two and three mutually unbiased bases. We 
then derive the optimal eavesdropping strategy for two mutually unbiased bases in dimension four 
and generalize the result to a quantum key distribution protocol that uses two mutually unbiased 
bases in arbitrary finite dimension. 
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CN ! I. INTRODUCTION 

x> : 

1^ . In the field of quantum information, quantum key distribution is the application which is more developed, to the 
point that already commercial prototypes exist. This fact is a good indicator of just how much attention the subject 
has received in the last years. It is therefore of primary importance to analyze in detail the security of the various 
schemes proposed. After the BB84 protocol, suggested originally by Bennett and Brassard in 1984 [lj and based on 
the transmission of single qubits, many generalized quantum key distribution protocols appeared in the literature: 



the six-state protocol for qubits UU, the generalization to qutrits in |4j and to ququarts in 5], and then subsequent 
generalizations to arbitrary dimensions [a, Q • Several aspects of the security of these protocols have already been 



in 



3 



analyzed 0, Q • Here we limit our attention to quantum key distribution protocols based on the transmission 
of single particles, and do not consider entanglement based schemes @. 

In this paper we analyze incoherent symmetric eavesdropping attacks on some generalizations of the BB84 and the 
six-state protocol, in which we use three- and four-dimensional systems and vary the number of mutually unbiased 
bases used. For each protocol we consider, our main purpose is to derive the eavesdropping strategy that is optimal 
■ with respect to the mutual information shared between Alice and Eve, Iae, for some given disturbance D. This 
l allows us to compare the robustness against eavesdropping of the various protocols. 
, 1 * i The paper is arranged in the following way: in the next section we introduce the most general eavesdropping 
strategy for a set of three-dimensional states and we impose the unitary and symmetry conditions. In Subsec. Ill Al 
we consider the cryptographic protocol suggested in 4], where, however, we use only two rather than four mutually 
unbiased bases for coding the information that Alice wants to communicate to Bob. In Subsec. Ill Bl we analyze the 
same scheme but with three mutually unbiased bases. In these sections we find the optimal eavesdropping strategy 
and we compare the results with those ones obtained by an optimal quantum cloning machine. The generalization to 
four-dimensional systems and the comparison with the corresponding results derived from cloning attacks 0, ITol Hi) 
is discussed in Sec. IIIII in a protocol with only two unbiased bases. Finally, in the Sec. IIVI we generalize the analysis 
to the case of two mutually unbiased bases with d-dimensional quantum states with arbitrary finite d. 



II. OPTIMAL EAVESDROPPING WITH THREE-DIMENSIONAL QUANTUM STATES 

In this Section we derive the optimal incoherent eavesdropping strategies for quantum cryptographic protocols 
based on the transmission of three-dimensional systems (qutrits) and with two and three mutually unbiased bases. 
We consider the general scenario where an eavesdropper intercepts the quantum system in transit from Alice to Bob, 
couples it to an ancilla by a unitary interaction, and then forwards the original, but now disturbed, quantum system 
to Bob while keeping the ancilla. We assume that Eve can store the ancilla until the public discussion between Alice 
and Bob has taken place, since during their discussion the measurement basis for each qutrit is revealed. 

The amount of information Eve can obtain from her system is determined by the strength of the interaction, and 
how she later measures the ancilla. The stronger the interaction the more information Eve can extract from the 
ancilla but with the cost of inducing a larger and larger disturbance on the system that Bob finally receives. There 
is therefore a certain trade off between the information she can gain and the disturbance that she introduces on 
the system in transit from Alice to Bob. In the following we optimize the information gain for a given value of the 
disturbance. 
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In three dimensions it has been shown that a generalization of the six-state protocol, which uses four mutually 
unbiased bases, i.e. 12 states, is more robust against eavesdropping than the two dimensional counter part. Here we 
analyze incoherent and symmetric attacks on three-dimensional quantum states in protocols which use two and three 
mutually unbiased bases. We remind that the word incoherent refer to an attack where Eve interacts with one system 
in transit at a time. 

Conventionally the first basis of the protocol corresponds to the computational basis, i.e. in a three-dimensional 
Hilbert space we denote it by {|0) , |1) , |2)}. Then, the most general symmetric eavesdropping strategy for qutrits is 
of the form 

\Q)\E) 1L x/I - D |0) |£ 00 } + ^1 |i)|£ 01 ) + yf \2)\E 02 ), 
U 



l)\E) ^ J%\Q)\E W ) + VT=D\1)\E 1X ) + JZ\2)\E 12 ), (1) 



\2)\E) yjf |0> |£ 20 > + y'f |1) |i?2i> +VT^D|2>|I? 22 >, 

where D is the disturbance introduced by Eve and F = 1 — D represents the fidelity of the state that arrives at Bob 
after the eavesdropping attack. We have indicated with \E) the initial state of Eve's system, while her states after 
the interaction are denoted \Eoq) > \Eio) , • • • and are all normalized. We point out that the dimension of the Hilbert 
space related to Eve's system is not fixed. 

In order to satisfy the unitarity of 14, the scalar products between Eve's output states have to obey relations of the 
form 



° {l 2 — ((Eij \E n ) + (E u \Eji)) + ^(E lk \E jk ) = 0, 

where i = 0,j = l,k = 2 and cyclic permutations. The requirement of symmetry reduces considerably the complexity 
of the analysis, because it reduces the number of parameters necessary to describe the most general eavesdropping 
attack. Moreover, it has been shown |12| that the symmetry argument can be applied without lack of generalization. 
The symmetry condition imposes some restrictions on the scalar products which characterize the unitary operation 
U used in Eve's eavesdropping strategy: the scalar products between the Eve's output states have to be invariant 
under the exchange of the indices (0, 1 and 2) in order to treat the computational basis states equally. Therefore it is 
possible to divide the scalar products into 6 different groups, each group defining a free parameter (x, y, z, t, w and 
s). In the following the index is k — 0, 1, 2: 



(Eu 


\Eij) 


= x, for j ^ i, 


(Eu 


\E jk ) 


= y, where i, j, k are all different, 


(Eij 


\E ik ) 


= z, where k are all different, 


(Eij 




= t, for j ^ i, 


(E i:j 


\E ki ) 


= w, where i, j, k are all different, 


(Eu 


\En) 


= s, for j ' ^ i; s is a real number. 



We will now specify the above strategy for various protocols using different numbers of mutually unbiased bases. 

A. Two mutually unbiased bases 

First we consider the cryptographic protocol suggested in Q with only two mutually unbiased bases, namely a 
generalization of the BB84 protocol to dimension d — 3. We choose the second basis to be the discrete Fourier 
transform of the computational basis 

|0') = ^(|0> + |1> + |2», 

|1'} = 4(|0>+«|1}+«*|2)), (2) 



73 v 



|2'> = 4?(|0> + a*|l) + a|2», 
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where a = e 2 ^. These two bases are mutually unbiased since \(i \ f) \ = l/\/3 with i,j = 0, 1, 2. 

We derive the optimal eavesdropping strategy for the quantum key distribution protocol which uses these two bases 
by imposing the same symmetry and unitarity conditions to the second basis of the protocol as it was done for the 
first basis. This further reduces the number of the parameters necessary to define the mutual information between 
Alice and Eve. 

The disturbance introduced by Eve to all possible input quantum states has the following form 

D( i) = l-F (i) =l-(i\g { ;] out \i), (3) 



where \i) is one of the possible states sent by Alice and Qg\ ut — Tte[W(|z) \E))((E\ (i\)U^] is the reduced density 
operator of the corresponding state sent on to Bob after the interaction with Eve. By imposing that the disturbance 
Dm takes the same value D for all 6 possible input states, and by writing the disturbance introduced through the 
eavesdropping transformation as a function of the scalar products of Eve's output states, we find the following 
simple relation among w, D and s: 

_ 1 - DRe(w) _ 3D 
S ~ ~ D 2(1 -DY { } 

For simplicity, we consider w to be real because only its real part appears in Eq. Q. Moreover, by imposing all 
the conditions discussed above, we can conclude that the remaining four groups of scalar products are zero, i.e. 
x — y = z = t = and (Ejj \Ejj) — with i,j = 0, 1, 2 (i ^ j). We can now identify three orthogonal sets of output 
states, {|-Eoo) , |£ai) , I-E22)}, {\E i) , \E 12 ) , \E 20 )}, {I-E02) , \E 10 ) , \E 21 )}. The first set corresponds to the case where 
the state has arrived correctly to Bob, which happens with probability F. The second and the third correspond to the 
cases where Bob obtains an error; in total this happens with probability D = 1 — F. Notice, however, the difference 
between the two sets of error states, the first of these sets corresponds to Alice sending i and Bob receiving i + 1, 
whereas the second corresponds to Alice sending i and Bob receiving i + 2 mod 3. 

To describe the efficiency of an eavesdropping attack, we evaluate the mutual information between Alice and Eve, 
which is the commonly used figure of merit. We will derive the optimal eavesdropping transformation for a fixed value 
D of the disturbance, by maximizing the mutual information Iae with respect to the free parameters of the strategy 
(i.e. the non-trivial scalar products between Eve's output states). In order to derive the expression of the mutual 
information between Alice and Eve, we introduce the general parametrization for the normalized output states 

\E 00 ) = u\d)+v\l)+v\2), 

\E n ) = w|5> +t*|l> +w|2> , (5) 
\E 22 ) = «|5)+«|l)+u|2>. 

Since s is real, in the above parametrization we can take the coefficients u and v to be real. Let us point out that in 
Eqs. (JHJ {|0) , |1) , |2)} represents an orthonormal basis, orthogonal to all the other output states of Eve's system, and 
that this particular parametrization is due to the fact that, according to the symmetry conditions imposed above, the 
overlaps of these three states must be equal. Eve later uses a standard von Neumann measurement [13j on the basis 
{\i}} to distinguish these states. If the outcome of her measurement is the state {|0)}, she will interpret this as if the 
state was |-Ebo)> etc. In this way her probability of guessing the state correctly is u 2 , and the total probability for 
making an error is 1 — u 2 = 2v 2 . 

Furthermore, we assume that the other two sets of states, {|-Em) , I-E12) , I-E20)} and {\E 2) ,\Eio) ,\E 2 i)}, are 
parametrized in a similar way where, instead of u and v, we find, respectively, two other real numbers, r and q, and 
the basis {|z)} is replaced by two other orthogonal bases {\i}} and {|«)}- Therefore Eve lets her system interact with 
the state in transit according to Eqs. Q and then, after listening to the public discussion between Alice and Bob, 
she performs a measurement. Eve's probability of guessing the qutrit correctly when Bob received it undisturbed is 
u 2 , and when Bob's state is disturbed her probability for guessing the qutrit correctly is r 2 . This makes it possible 
to compute Eve's probability of guessing the qutrit correctly, P(E), 

P(E) = F u 2 + D r 2 . (6) 

By using the symmetry conditions 2uv + v 2 = s and 2rq + q 2 = w, and by exploiting Eq. flljl. u 2 and r 2 can be 
expressed as functions of D and w 



u = 4> 3 (D,w) 



3 + 2.DO-1) 2y/2D[3 - 2D(2 + w)](l + 2w) 



r 2 



9(1 -D) 9(1 — D) 

X 3 (w) = -(5 - 2w + 4^1 + w - 2w 2 Y (7) 
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Based on these probabilities it is now possible to compute the mutual information between Alice and Eve, Iae,3 m 
terms of the disturbance D and the parameter w. There are two different cases: (f ) the qutrit has arrived correctly 
to Bob; this happens with probability F = 1 — D, in which case Eve has probability 3 (D, w) for guessing the state 
correctly, (2) Bob has gotten an error, this happens with probability D, in which case Eve has probability X 3 (w) for 
guessing the state correctly. This means that the mutual information between Alice and Eve becomes 



where I 3 (x) = 1 + H 3 (x) = 1 

IaeAD,w) = 1 + (1-D) 



Iae,s = F hiMD, w)) + D I 3 (X 3 (w)), 
x\og 3 x + (1 — x) log 3 [(l — x)/2\. Hence, 



(8) 



D 



4> 3 (D, w) log 3 4> 3 (D, w) + [l- 4>z{D, w)] log 3 

1 - \ 3 (w 



X 3 (w) log 3 X 3 (w) + [1 - X 3 (w)} log 3 



(9) 



where we have used the relation F = 1 — D. Through cumbersome calculations (see the Appendix lAl for details), we 
can prove that, for fixed D, Iae,3{D, w) is maximized in correspondence of the value w = |(| — D), which corresponds 
to (j) 3 (D,w) = X 3 (w) and therefore Iae,3(D,w) is the optimal mutual information between Alice and Eve and takes 
the following simple form: 



Iae,z{D, w) = 1 + (D, w) log 3 </> 3 (D, w) + [1 - fo(D, w)} log 3 



l-<f>a(D,w) 



(10) 



Notice that Eve needs to employ an ancilla with dimension nine, or equivalently two three-level systems, to implement 
the optimal attack. 

As regards Bob, his mutual information with Alice decreases with increasing disturbance as follows 



IabAD) = 1 + (1 - D) log 3 (l - D) + Dlog 3 ~ 



(11) 



These results are plotted in Fig. As we can see, the information curves for Bob and Eve intersect at the critical 
value for the disturbance D r ..i = 0.2113. For any value of the disturbance smaller than this critical value the protocol 
is guaranteed to be secure 



B. Three mutually unbiased bases 

We now derive the optimal strategy for an extension of the above protocol, namely with three rather than two 
mutually unbiased bases. As before, the first basis is conventionally chosen as the computational basis {|0) , |1) , |2)}, 
while the second basis is now defined as 

10") = -±=M0) + |1} + |2)), 
|1"> = ^=(|0) + a|l> + |2)), 

|2") = -J=(|0> + |l>+a|2», (12) 

where a = e 2 ? 5 " . 

Similarly, the third basis is obtained by substituting in the above equations a with a* . Even if in general in dimension 
higher than two different sets of mutually unbiased bases are not unitarily equivalent, we have checked that our results 
do not depend on the choice of the three mutually unbiased bases, so we use these three bases for convenience in the 
calculations. 

Following the same procedure as above, we obtain the following simple relation among D, w and s 

iug+2-ag 

2 1-D v ; 

where s and w are defined at the beginning of Sec. |nj By imposing all the constraints as in the previous case, we can 
show that w is a real number and that all the other scalar products are zero; in other words, there are again three 
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orthogonal sets of states, {\E QQ ) , \E n ) , \E 22 )}, {\E Q1 ) , \E 12 ) , \E 20 )}, {\E 02 ) , \E 1Q ) , \E 21 )} , i.e. x = y = z = t = 
and {Eij \E iS ) = with i,j = 1,2,3 (i ? j). 

In this case, we introduce the following general parametrization for the set of normalized states of Eve 

\E 00 ) = u|6)+»|l)+»|2), 
\E n ) = «|6)+u|l)+»|2), 

\E 22 ) = w|6)+»|l) + u|2), (14) 

where, without loss of generality, we can take the coefficients to be real. Again we assume that the other auxiliary 
states, {l-Eoi) , \Ei 2 ) , l-E^o)} and {\Eq 2 ) , |£io) , l-E^i)}, obey to the same parametrization where, instead of u and v, 
we find, respectively, two other real numbers, r and q. 

Analogously to the previous case, after listening to the public discussion between Alice and Eve, Eve measures 
her system and the probability of guessing the qutrit correctly, P(E), is given by Eq. ©. By using the symmetry 
conditions, 2uv + v 2 = s and 2rq + q 2 = w, it is possible to express u 2 and r 2 as functions of D and w as follows 



u 2 — /i(-D, w) — 



D{w + 2) 2- v /2D[3 + D(io-4)](l-u;) 



9(1 -D) 9(1 -D) 

r 2 = v{w) = i ^5 - 2w + 4\/l + w - 2w 2 ^j . 

Again, from these probabilities we can compute the mutual information between Alice and Eve 

Iae,3 = F I 3 {n(D,w))+D h{v{w)). 
The mutual information between Alice and Eve then takes the explicit form 

l-n(D,w) 



(15) 



(16) 



D 



fj,(D, w) log 3 fi(D, w) + [1 - n{D, w)\ log 3 

1 — v{w) 



v{w) log 3 v(w) + [1 — v(w)] log 



(17) 



Notice that, in contrast with the previous case, here we have found no simple analytical solution for the optimal 
mutual information between Alice and Eve. Therefore in Fig. Q]we plot a numerical solution for the optimal expression. 
The mutual information between Alice and Bob takes the form (|ll|l . as in the previous case. The information curves 
for Bob and Eve intersect at a value of the disturbance D c ,3 — 0.2247, which is larger than D c , 2 = 0.2113. These two 
values have also to be compared to the critical value D C 4 — 0.2267 6] of the protocol that employs four mutually 
unbiased bases, which is the maximum number in dimension three. 

As expected, the critical value increases for increasing number of mutually unbiased bases, but it increases weakly. 
On the other hand the key generation rate decreases (the key generation rate decreases as the inverse of the number 
of bases employed). Therefore, in a realistic scenario the optimal choice for the number of bases to be employed in a 
protocol will depend on a convenient balance between the two trends. 

Finally, we compare the above results with the ones obtained by optimal quantum cloning attacks. The cases with 
two and four bases are studied analytically in 0, while in 0, UJ the case with three mutually unbiased bases is 
studied numerically. The results obtained both with the most general unitary eavesdropping strategy and with the 
optimal quantum cloning machine are exactly the same. Therefore the quantum cloning machine would represent an 
optimal eavesdropping strategy for these quantum key distribution protocols. 
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FIG. 1: Mutual Information for Alice/Bob (I(AB)) and Alice/Eve as a function of the disturbance D, for three-dimensional 
quantum states in a scheme with two (I2(AE)), three (I3(AE)) and four (I4(AE)) mutually unbiased bases. The latter curve 
was derived in In. 



III. OPTIMAL EAVESDROPPING WITH FOUR-DIMENSIONAL QUANTUM STATES 

We will now derive the optimal eavesdropping strategy for two mutually unbiased bases in dimension d = 4. Now let 
us introduce the computational basis {|0) , |1) , |2) , |3)} and write the most general unitary symmetric eavesdropping 
strategy for a set of four-dimensional quantum states (ququarts) : 

\i) \E) ±L VT^D \i) \E U ) + y p>\i + i) \Ei i+x) + yff\i + 2) \Ei i+2 ) + yf§\i + 3) \E t i+3 ) , (18) 

where i = 0, 1, 2, 3 and the index additions are taken modulo 4. 

In order to satisfy the unitarity of U, the scalar products between Eve's output states have to obey to constraints 
similar to the three-dimensional case and, for the symmetry of the problem, we have again a classification of Eve's 
output states into six sets of scalar products, each defining a free parameter. The scalar products have to fulfill the 
following conditions 

(En \Eij) = x, for ij^j, 

(En \Ejk) = y, where k are all different, 

(Eij \Eik) = z, where i, j, k are all different, 

(Eij \Ejh) = t, for h all different, 

{Eij \Ehk) = w, where j ^ i, (h = j and k = i) or (h, k, i,j all different); it turns out that w is a real number, 

(En \Ejj) — s, for i ^ j; s is also real. 

Let us consider the protocol, suggested in where the first basis is the computational basis and the second basis, 
connected by a discrete Fourier transform to the first one, is defined as 

10') = i(|0> + |l) + |2> + |3», 

|1') = |(|0)-|1) + |2)-|3)), (19) 

|2') = |(|0)-|1)-|2) + |3)), 

13') = |(|0) + |1)-|2)-|3)). 
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By imposing the additional conditions that the disturbance must be the same for all eight possible states sent by 
Alice the number of free parameters is further reduced because it turns out that x = y = z = t = 0. We can then 
derive the following expression for s as a function of D and w 

1 - wD 4 D 

Again, we introduce the following parametrization for Eve's output states, by generalizing the procedure followed in 
the three-dimensional case 

\E 00 ) = u |0> + w |1> + « |2> + « |3> , 

\E U ) = v\0)+u\l)+v\2)+v\3), (21) 
\E 22 ) = v|0)+t>|l>+u|2}+t;|3}, 
\E 33 ) = «|0)+«|l)+t;|2)+u|3). 

where u and v are real numbers. 

Analogously to the three-dimensional case, a similar parametrization (with r, q real) is chosen for the other three sets 
of states {\E 01 ) , \E W ) , \E 23 ) , \E 32 )}, {\E 02 ) , \E 13 ) , \E 20 ) , \E 31 )} and {\E 03 ) , \E 12 ) , \E 21 ) , \E 30 )}. After the public 
discussion between Alice and Bob, Eve performs a measurement and has the following probability, P{E), to make the 
correct estimation of the qutrit 

P{E) = F u 2 + D r 2 , (22) 

where 



2 4-2P(l-3w) V3J(l + 3 W )[4-^(5 + 3 W )] 
U = <MA™) = 16(1 - Z?) +2 \Q(\~~~D) ' (23) 



r 2 



\ 4 ( w ) = l($ - 3w + 3a/i + 2w - 3w 2 ) . (24) 



The above expressions are calculated by exploiting the normalization conditions, the symmetry conditions and using 
Eq. (H3). 

From the above probabilities the mutual information between Alice and Eve can be derived 

Iaea = F h(MD, w)) + D / 4 (A 4 H), (25) 

where I±{x) = 1 + H^{x) = 1 + a;log 4 x + (1 — x) log 4 [(l — x)/3\. 

The mutual information has now to be optimized as a function of w. This can be done analytically, following the 
same procedure as in the three dimensional case reported explicitly in the Appendix. It turns out that the solution 
of the optimization is given by the value w = | (| — D) and the optimal mutual information between Alice and Eve 
is then given by 

IaeAD, w) = l + fa{D, w) log 4 MD, w) + [1 - MD, w)} log 4 1 ~M D ^ . ( 26 ) 

This expression has to be compared with the mutual information between Alice and Bob, which is now given by 

Iaba(D) = 1 + (1 - D) log 4 (l - D) + D log 4 j . (27) 

These curves are plotted in Fig. 2, and compared to the optimal one corresponding to five mutually unbiased bases, 
conjectured in jfj. The two critical values are D c , 2 — 0.25 for two mutually unbiased bases and D c ,5 = 0.2666 for five 
mutually unbiased bases. As we can see, the robustness of the protocol increases as the number of mutually unbiased 
bases increases, at the expense of a considerable reduction in the key generation rate, which goes from 1/2 to 1/5. 

Finally, we compare the results above with the ones corresponding to the relative optimal quantum cloning machines, 
as studied in 0; as in the case of qutrits, the curves for the optimal mutual information between Alice and Eve are 
the same. 
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FIG. 2: Mutual Information for Alice/Bob (I(AB)) and Alice/Eve as a function of the disturbance, for four-dimensional 
quantum states in a scheme with two (I2(AE)) and five (I5(AE)) mutually unbiased bases (the latter curve was conjectured in 
I). 



IV. GENERALIZATION TO d-DIMENSIONAL QUANTUM STATES 

In this Section we generalize the above analysis to the case of two mutually unbiased bases with d-dimcnsional 
quantum states (qudits) with arbitrary finite d. After introducing the computational basis {\k}} with k = 0, d— 1, 
the most general symmetric eavesdropping strategy for qudits takes the form 

2)\E ll+2 )+ ... +^f^\i + d-l)\E ii+d _ 1 ),(28) 

where i = 0, 1, 2, 3, d — 1 and the index additions are taken modulo d. 

Now we consider the cryptographic protocol where the two mutually unbiased bases are given by the computational 
basis {|0) , |1) , ...} and its Fourier transformed 

d-l 

I?) ' Ve 2 -™|fc), (29) 

with I = 0, ...,d- 1. 

We follow the same procedure as in the previous sections, by imposing the symmetry conditions and the requirements 
that all possible 2c? states sent by Alice are equally disturbed. In this way we obtained that many scalar products 
among Eve's output states are zero and the number of free parameters is reduced. 

In particular, it is possible to divide Eve's output states into d orthogonal sets: one of these sets is 
{l-E'oo) i l^n) i l-^d— l d— while the other ones assume a particular form according to the parity of the dimension 
of the Hilbert space, d. 

If d is odd, the other d — 1 sets are formed by , \E i+1 2 ) , \E i+2 3) , \E i+d -i 0)}, where i = 0, 1, d — 1. 

Instead, if the dimension d of the Hilbert space is even, we have the following d — 1 sets: 

{\Eoj) , \Ei , \E d -i j+ d-i)} where j - 2, 4, d - 2. 



{\E 0j ) , \Ei j-i) , \E d -x j-d+i)} where j = 1,3, ...,d- 1. 

Independently of the parity of d, the scalar products between any two states, belonging to one of these d—1 sets, are 
always the same and equal to a free parameter w. Moreover, analogously to the case of qutrits and ququarts, there 
is the additional condition (Ea \ Ejj) — s for i =/= j. 
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Combining all the constraints of the problem, the generalized relation among D, w and s is as follows 

1-wD d D 



1-D d-lD-l 



(30) 



After introducing the proper parametrization for Eve's output states and the relative set of probabilities for her 
measurement, we obtain the mutual information between Alice and Eve and then we optimize it with respect to the 
free parameter w. Finally the optimal mutual information between Alice and Eve has the following form 



IaeAD, w) = 1 + MD, w) log, MD, w) + [1 - MD, w)} log d 1 ^ d ^ w \ 



(31) 



where 
and 



d?{l-D) 



d + D[-2 +{d- 2)(d - l)w] + 2yJ(d - l)D[l + (d - l)w}{d - D[l + d+(d- l)w}} , (32) 



d-1 



w 



d-1 



D 



For any value of d, the function Iae,<i(D) is the same as that one obtained in with a cloning-based attack. This 
expression has to be compared with the mutual information between Alice and Bob, which is given by 



IabAD) = ! + {!- D) log d (l -D) + D log rf 



D 



d-1 



(33) 



Analogously to the cloning attack, we find the following analytical expression for the critical disturbance, D c , as 
function of d 



(34) 



The above expression proves that the robustness of the quantum channel increases as the dimension of the quantum 
system used in the protocol increases. 



V. CONCLUDING REMARKS 



In this paper we study some different quantum key distribution protocols in order to compare their robustness 
against eavesdropping. A protocol is said to be more robust if it tolerates a higher disturbance and still allows Alice 
and Bob to generate a secure key. We have derived the optimal eavesdropping strategy for each protocol, concentrating 
on symmetric and incoherent attacks and evaluated the optimal mutual information between Alice and Eve for a given 
disturbance. We note that the robustness of quantum key distribution increases with the dimension of the space, 
hence reflecting the fact that since there are more states, an error can be distributed among more states. Increasing 
the number of mutually unbiased bases used also improves the robustness against eavesdropping. However, increasing 
the number of bases has to be weighted against a lower key generation rate since the probability that Alice and Bob 
used the same basis goes down. 

We have compared our results with the ones obtained under the assumption that optimal asymmetric quantum 
cloning machines [^. ll0llTT| provides optimal eavesdropping. In this comparison we note that the values of the critical 
disturbance are always the same and therefore we can conclude that the quantum cloning machine represents the 
optimal eavesdropping strategy of the quantum key distribution protocols studied in this paper. 



APPENDIX A: THE OPTIMAL MUTUAL INFORMATION ALICE/EVE 

In this Appendix we show the analytical calculations in order to maximize the mutual information between Alice 
and Eve in a protocol with two mutually unbiased bases. We analyze in detail the three-dimensional case, but the 
proof can be easily extended to higher dimensions. 
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Recall that in a protocol with two bases the mutual information Alice/Eve for three-dimensional quantum states, 
as a function of the disturbance (D) and the free parameter (w), has the following analytical expression: 



WA«) = i + (1--D) 



D 



<j> 3 (D, w) log 3 03 (D, w) + [l- foiD, w)} log 3 

I-A3H 



A 3 (to) log 3 A 3 (w) + [1 - A 3 (w)] log 3 ■ 



(Al) 



where </> 3 (.D, w) and As(w) are given in Eqs. (JJJ. Using the normalization of the ancilla states and taking into account 
the expression we can prove that 



d w I A E,3(D,w) 



= 



(A2) 



In fact, when w = |^| — D^j , the following relations are satisfied 

{ </>a(D,w) = X 3 (w) 



d m <t> 3 (D,w) 
d w X 3 (w) 



D 
D-l 



d w lAE,3(D,w) 



= 0. 



Therefore the stationary points of Iae,3 are on the plane w = | ^| — -D^j and, because of the concavity of the mutual 

information Alice/Eve, Iae,3{D, w) is the maximal mutual information that Eve can extract from the quantum channel 
Alice/Bob. The mutual information therefore has the following expression: 



Iae,3(D, w) = 1 + </> 3 (D, w) log 3 03 (A w) + [1 - «fe(£>, w)] log 



(A3) 



where w 



In order to prove the concavity of the mutual information Alice/Eve, Iae,3(D,w), let us consider the auxiliary 
two-variable function, /(a, 6), as follows 



f(a, b) = 1 + (1 - D){a\og[a] + (1 - a) log[(l - a)/2]} + D{blog[b] + (1 - b) log[(l - 6)/2]}. 



(A4) 



Now let a(-D, w) = </> 3 (-D, w) and = A3(ui). Because the values of </> 3 (-D, w) and A3(u>) are in the range [|, 1], we 
have 



5„/(a, 6) = (1 - £>) log[2a/(l - a)] > 0, d b f(a, b) = (1 - D) log[26/(l - 6)] > 0. 
Then the second derivatives are 



d a ,af(a,b) = - ° > 0, 
a(l — a) 



db, b f(a,b) = ,i D . > 0. 



6(1 - 6) 



whence 



and 



d w I A E,3{D,w) = d w f{a 7 b) = d a f(a,b)d w a + d b f(a,b) 



db 
dw 



d w , w lAE,3(D,w) = d w , w f(a,b) = d a , a f(a,b)(d w aj + d a f(a,b)d W}W a + d b ^ b f(a,b)(^-^j +d b f(a,b) 
Combining all these equations together, we obtain 



d w , w lAE,3{D,w) = (1 - D) 



1 



<t>{D,w)[l-<t>{D,w)] 
+D 



[d w cb{D,w)} 2 + \o. 
1 



X(w)[l - \(w)] 



[A (w)Y+log 



l-cj>(D,w) 

2\(w 



d w ^4>{D,w) 



d 2 b 
dw 2 



+ 



(A5) 
(A6) 

(A7) 

(A8) 



1 - \{w) 



A H 



< 0. 



(A9) 



Recall that < D < 2/3. The parentheses on the right hand side of Eq. (|A9(I are always negative in the domain of 
definition of the function Iae,3(D, w). Therefore 8 WjW Iae,3(D, w) < and it follows that the function Iae,3(D, w) is 
concave. 

The generalization to arbitrary dimension, which leads to the solution w = (^p — D), is then straightforward. 
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